mirror of
https://github.com/django/django.git
synced 2025-11-25 05:04:26 +00:00
Fixed CVE-2021-28658 -- Fixed potential directory-traversal via uploaded files.
Thanks Claude Paroz for the initial patch. Thanks Dennis Brinkrolf for the report.
This commit is contained in:
parent
78fea27f69
commit
d4d800ca1a
9 changed files with 159 additions and 23 deletions
|
|
@ -4,6 +4,7 @@ from . import views
|
|||
|
||||
urlpatterns = [
|
||||
path('upload/', views.file_upload_view),
|
||||
path('upload_traversal/', views.file_upload_traversal_view),
|
||||
path('verify/', views.file_upload_view_verify),
|
||||
path('unicode_name/', views.file_upload_unicode_name),
|
||||
path('echo/', views.file_upload_echo),
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue